The post has been translated automatically. Original language: Russian
Today it is difficult to imagine a website without HTTPS. Nevertheless, there are still projects whose owners consider an SSL certificate to be an optional option. In practice, this has not been the case for a long time.
Firstly, HTTPS protects the data that is transferred between the user and the site. This is especially important if visitors submit applications, register, or enter any personal information.
Secondly, modern browsers warn users if the site is running without a secure connection. For many people, such a message is already enough to close the tab and not return.
There is an opinion that SSL is needed only by online stores or large services. In fact, the certificate should be installed even on a regular corporate website or landing page. Today, this is more of a standard than an additional feature.
Over the years, we have repeatedly come across a situation where website owners have postponed switching to HTTPS, believing that this can be done later. But after the warnings appeared in the browser or the decrease in customer trust, the issue had to be resolved urgently.
When choosing a certificate, you don't always have to chase after the most expensive option. A standard SSL certificate is sufficient for most small projects. It is much more important to install it correctly and extend it in a timely manner.
It is also worth remembering that installing a certificate by itself does not make the site completely secure. It is equally important to update the CMS regularly, use complex passwords, monitor server security, and back up data.
If you are launching a new project, it is better to include SSL connection in the list of required tasks even before publishing the site. This not only increases the level of security, but also builds trust on the part of users from the very first days of operation.
Today HTTPS is no longer an advantage. This is a basic requirement, without which a modern website looks incomplete and raises unnecessary questions from visitors.
Недавно поймал себя на мысли, что многие проблемы с доступами возникают вовсе не из-за хакеров. Чаще всего их создаем мы сами.
За годы работы приходилось видеть самые разные способы хранения паролей. Кто-то записывает их в блокнот, кто-то держит в заметках телефона, кто-то отправляет коллегам в мессенджере. Самый необычный вариант, который встречался, был файл с названием «Пароли новые окончательные 2».
Пока команда небольшая, кажется, что такой подход вполне работает. Но проходит время, появляются новые сотрудники, меняются подрядчики, запускаются дополнительные сервисы, и разобраться, какой пароль актуальный, становится все сложнее.
Отдельная история начинается, когда один сотрудник увольняется. Если доступы нигде не систематизированы, приходится срочно менять пароли, восстанавливать учетные записи и выяснять, где вообще находятся нужные данные. Иногда на это уходит гораздо больше времени, чем хотелось бы.
Сейчас есть много удобных менеджеров паролей, которые позволяют безопасно хранить доступы и делиться ими внутри команды. Это заметно удобнее, чем искать нужную комбинацию символов в переписке двухлетней давности.
Есть еще одно правило, которое кажется очевидным, но его часто игнорируют. Рабочие доступы лучше не смешивать с личными аккаунтами. Такой подход упрощает передачу проектов и снижает количество неприятных ситуаций, если кто-то меняет место работы.
Мы заметили одну интересную вещь. Чем раньше компания начинает наводить порядок с доступами, тем меньше организационных проблем возникает в будущем. Особенно когда команда постепенно растет.
Безопасность начинается не с дорогих решений и сложных технологий. Иногда достаточно навести порядок в тех вещах, которыми команда пользуется каждый день.